Digital Health Blog
Legal & Policy Insight to Empower the Evolution of Health Care
Never Miss an Update
House passes KIDS Act, sending online child safety debate to the Senate
On July 7, the House of Representatives passed the KIDS Act (H.R. 7757) in a vote of 267-117, advancing a package of online child safety measures aimed at establishing baseline federal protections for minors while allowing states to enact stronger safeguards. The legislation reflects years of congressional efforts to strengthen protections for children online and follows a bipartisan agreement reached in the House Energy and Commerce Committee.
The package includes provisions requiring AI chatbots to disclose that they are not human, restricting minors’ access to disappearing messages, and requiring age-verification technologies for certain content. The bill also establishes federal standards for children’s online safety while preserving states’ ability to adopt more stringent protections and does not preempt state artificial intelligence laws.
While House passage marks a significant milestone, substantial challenges remain before the legislation can become law. The House and Senate continue to differ on key elements of child online safety policy, including age-verification requirements, First Amendment concerns, and whether online platforms should be subject to a “duty of care” obligation requiring them to design products with children’s safety in mind. While this legislation may not see final passage this Congress, this has been an ongoing bipartisan area of interest as Congress looks to find agreement on how to regulate artificial intelligence and work will likely continue into the next Congressional session.
California expands sales tax to SaaS and digital products
On June 29, 2026, California Governor Gavin Newsom signed SB122 into law, expanding the state sales tax base to include SaaS, electronically delivered software, and certain digital products beginning in 2027. The legislation generally treats many digital products as taxable tangible personal property and adopts a customer-based sourcing methodology. For remotely accessed or electronically delivered products, sales are sourced to the purchaser’s “known address” in California.
The new tax classifications will require both software providers and customers to reassess their sales and use tax compliance obligations. These changes also may increase costs for healthcare providers and other end users as software vendors seek to pass through newly imposed sales and use tax liabilities. Users may also see increased compliance costs associated with implementing the new regime and amending existing contractual arrangements.
Illinois’ AI Safety Measures Act reflects the growing patchwork of state-level AI regulations
Illinois Governor J.B. Pritzker signed the Artificial Intelligence Safety Measures Act into law on July 6, 2026. The legislation requires developers of frontier AI models to develop and publish a transparency framework describing how they apply recognized industry standards, evaluate model capabilities, and assess and mitigate risks of catastrophic harm to individuals and the public.
The Illinois measure builds on transparency and accountability requirements included in California’s the Transparency in Frontier Artificial Intelligence Act and New York’s the Responsible AI Safety and Education (RAISE) Act, both enacted in late 2025. Like those laws, the Illinois framework imposes a range of obligations on developers of frontier models, including the publication of transparency reports and AI safety frameworks, incident reporting requirements, implementation of cybersecurity safeguards, and processes for identifying and responding to critical safety incidents.
The new law also includes, for the first time, a requirement that large frontier model developers undergo annual independent third-party audits evaluating model risks, safety controls, and mitigation measures. These audits must be conducted in accordance with accepted auditing standards and recognized industry best practices, signaling a shift from voluntary commitments toward more formal oversight and accountability mechanisms.
As transparency and accountability continue to emerge as central pillars of AI governance, particularly in healthcare, these disclosure and audit requirements may provide healthcare organizations with valuable information to support the assessment, procurement, monitoring, and governance of AI-enabled tools that incorporate frontier models. More broadly, the enactment of this law underscores the increasingly complex compliance landscape facing AI developers and deployers as states continue to advance AI-specific regulatory frameworks while federal lawmakers debate the appropriate scope and structure of national AI regulation. The result is a growing patchwork of state requirements that may create additional compliance, governance, and operational challenges for organizations deploying AI systems.
FDA authorizes first Software as a Medical Device incorporating a patient-facing LLM
Digital health company UpDoc announced that it received Food and Drug Administration approval for what the company describes as the first Software as a Medical Device (“SaMD”) incorporating patient-facing large language models for medication management purposes. The UpDoc platform, designed on previously approved tools to assist in management of type 2 diabetes medication, integrates with electronic health records and existing clinical workflows and allows patients to submit information to produce treatment plans generated in accordance with clinician-defined protocols.
While this clearance indicates the FDA’s willingness to authorize certain AI-enabled clinical tools, it does not establish a required approval pathway for all LLM-based healthcare products. Federal and state regulators continue to pursue multiple oversight approaches to regulating AI in health care, including an increasing number of states expressing interest in facilitating patient access to AI-enabled care through regulatory sandbox programs. Entities developing clinical and patient-facing AI technologies should consider governance and legal strategies calibrated to the specific intended use of the product at issue, as well as the implementation of protocols sufficient to demonstrate the safety, effectiveness, and reliability of the underlying AI technology.
TEFCA oversight and expansion
The U.S. Department of Health and Human Services (HHS), through the Office of the National Coordinator for Health Information Technology (ONC), announced new oversight measures for the Trusted Exchange Framework and Common Agreement (TEFCA), the national interoperability network designed to facilitate secure electronic exchange of health information. ONC has awarded a contract to enhance audit, review, and compliance functions and is conducting additional reviews of Qualified Health Information Networks (QHINs) and participating organizations to ensure adherence to TEFCA requirements. HHS also reported that TEFCA has grown from approximately 10 million exchanged health records to more than 1 billion records in less than one year.
CMS Announces New Technology Office
The Centers for Medicare & Medicaid Services (CMS) has announced the establishment of a new organizational component, the Office of Health Technology and Products (OHTP), effective June 9, 2026. OHTP is intended to provide enterprise-wide leadership and oversight of CMS’s health care technology modernization efforts, as well as the development and management of digital products supporting Medicare, Medicaid, the Children’s Health Insurance Program (CHIP), and other CMS-administered programs. The office will operate in coordination with the CMS Chief Information Officer (CIO).
OHTP will include several functional components, including the Open Source Program Group, the Standards & Interoperability Group, the Product Development Group, and Digital Services at CMS. This organizational change aligns with the Administration’s broader efforts to accelerate the digital transformation of CMS and modernize the agency’s technology infrastructure.
Trump Administration Issues Scaled-Back AI Executive Order
The Trump administration has issued a new executive order on artificial intelligence that emphasizes cybersecurity safeguards while pulling back from more stringent federal oversight proposed earlier. The directive introduces a voluntary review process requiring companies to submit advanced AI models to the government 30 days before public release—shortened from an earlier 90-day proposal—alongside new efforts to coordinate with industry on identifying and addressing security vulnerabilities.
Framed as a balance between innovation and risk mitigation, the order is narrower than expected and avoids mandatory licensing or preclearance requirements, reflecting industry concerns about overregulation. At the same time, it signals growing urgency within the administration to address national security risks posed by increasingly powerful AI systems, including steps to strengthen federal network defenses and expand collaboration with critical infrastructure partners.
Bipartisan Lawmakers Release Draft “Great American AI Act”
Reps. Jay Obernolte (R-CA) and Lori Trahan (D-MA) have unveiled a bipartisan discussion draft of the Great American AI Act, a proposal designed to establish a clear federal framework for governing artificial intelligence in the United States. Released to solicit public and stakeholder feedback ahead of formal introduction, the draft aims to balance rapid innovation with safeguards by promoting U.S. leadership in AI, setting consistent national standards to avoid a fragmented state-by-state approach, and introducing stronger accountability and protections for workers, consumers, and national security as the technology continues to evolve. While this is the first comprehensive bipartisan legislative marker put out this Congress, the draft has already received pushback from members of both parties. House Democrats have mainly been concerned of the inclusion of language to preempt state laws for at least three years. The Democratic House Commission on AI has indicated it does not support the draft in its current form. House Republicans are concerned changes could inhibit innovation in the space.
Still, the bipartisan nature of the draft does indicate areas of some agreement that could be worked out further through the Committee process or other iterations of the bill.
Joint Commission Launches AI Governance Certification for Health Care
The Joint Commission launched its Responsible Use of AI in Healthcare (RUAIH) certification program, a voluntary certification recognizes hospitals and health systems that have established the governance structures, safeguards, monitoring processes, and workforce education needed to deploy AI responsibly. The certification standards are organized around five major areas: (1) governance; (2) effective data management; (3) risk and bias reduction; (4) monitoring, evaluating, and validating safety, performance, and responsible use; and (5) transparency, education, and training. The certification program does not evaluate or certify individual AI products or appropriate use cases. Rather, it assesses whether organizations have implemented sound governance and responsible-use practices.
Paralleling this announcement, the Coalition for Health AI (CHAI) released a complementary series of in-depth governance playbooks address core governance elements such as organizational AI policy and oversight committees, risk and impact assessments, lifecycle management, responsible data use, and third-party vendor oversight. The playbooks operationalize the joint guidance the organizations issued by CHAI and the Joint Commission in September 2025 and are intended to provide a practical framework for organizations pursuing the Joint Commission’s RUAIH certification.
CHAI Releases Best Practice Guides for Responsible AI in Medicaid
The Coalition for Health AI (CHAI) also announced a new Best Practice Guide aimed at helping states, developers, and health organizations responsibly deploy artificial intelligence in Medicaid eligibility processes. Developed with input from more than 40 health care organizations, the guidance provides practical, role-based recommendations for high-stakes functions like enrollment and eligibility adjudication, while emphasizing transparency, fairness, and human oversight.
Designed as a timely resource ahead of federal implementation deadlines, the guide seeks to help modernize Medicaid operations, reduce administrative burden, and minimize the risk of inappropriate coverage loss—ensuring AI supports efficient processes without compromising patient access or equity.